CVE-2013-5160

iPhone OS < 7.0.2 - Unauthenticated Passcode Bypass via Emergency-Call Button Taps

Title source: llm
STIX 2.1

Description

Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by making a series of taps of the emergency-call button to trigger a NULL pointer dereference.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5957
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Sep/msg00009.html

Scores

EPSS 0.0034
EPSS Percentile 26.8%

Details

CWE
CWE-264
Status published
Products (2)
apple/iphone_os 7.0
apple/iphone_os < 7.0.1
Published Sep 28, 2013
Tracked Since Feb 18, 2026